27
submitted 2 months ago by cm0002@lemy.lol to c/privacy@programming.dev
you are viewing a single comment's thread
view the rest of the comments
[-] DFX4509B@lemmy.wtf 8 points 2 months ago* (last edited 2 months ago)

Cloudflare is about as bad, and the alarming thing is, Lemmy instances in particular tend to use that a lot when Altcha, Anubis, and go-away exist for if you must have a captcha of some kind.

If a hostile government doesn't like a given site, they could just have Cloudflare block it, where the self-hosted captchas I just mentioned don't necessarily have that problem.

Like, a Fediverse instance using Cloudflare, which is going against their best interest when the Fediverse is supposed to be an open and decentralized platform that's somewhat censorship-resistant, is really stupid when you got three open and self-hosted captcha alternatives you can use instead if you absolutely need a captcha. Using Cloudflare for this is opening the door for censorship of your instance if a hostile government suddenly decides your instance needs to be blocked.

As for Google reCAPTCHA, there's an even worse hypothetical I thought of than what is already on the table: Couldn't Google build a stripped-down version of Play Integrity into Chrome specifically for passing their captchas, and effectively lock most of the web into Chrome on desktops regardless of OS because vanilla Chromium and other Chromium forks and the FF browsers, and other alternative browsers such as Servo, Ladybird, or Safari, wouldn't have that stripped-down Play Integrity that Chrome would hypothetically have and thus wouldn't be able to pass Google's captchas if they actually pulled that?

this post was submitted on 27 Jun 2026
27 points (93.5% liked)

Privacy

5082 readers
267 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS